Cointime

Download App
iOS & Android

How to Stay Safe in DeFi: A Simple Guide to Evaluate Project Safety

The collapse of FTX proved the importance of self-custody and risk management.

But it’s so easy to lose money in DeFi if you are not careful with many exploits, rug pulls, contract bugs around.

In this blog I’d like to share how to evaluate safety of DeFi protocols to protect your assets.

It’s great if you’re an experienced smart contract developer and can verify the code yourself. But most of us aren’t.

It leaves us with no other choice, but to evaluate projects based on other data, that involves some degree of trust.

Total Value Lock, ultimate proof of security?

It’s no secret that the majority evaluate DeFi projects by how much value is deposited to the smart contracts. So, TVL is the ultimate proof of trust.

The higher the Total Value Locked, the higher the implied security of a protocol. If a lot of money is deposited, it means ‘someone’ did due diligence, and that protocol is secure.

Unfortunately, it gives a false sense of security. And high TVL protocols are actively targeted by hackers. At the same time, low TVL doesn’t mean a protocol is not secure.

Take a look at the top DeFi protocols by TVL.

  • Do you think that the TVL represents the level of security/safety?
  • Is there any protocol you wouldn’t trust with your money? Why?

There might be biases in you based on what you read online.

Trust, but verify?

‘Don’t trust, verify’ is the reason we have smart contract audits.

If that wasn’t the case, we might not need audits, because code is open source and community could find all the issues in the code. Yet the community might not have the right motivation, incentives or expertise to verify code.

Auditors are supposed to have the right technical expertise, but at the end of the day, we also have to trust them to do the right job.

Remember Twitter backlash against Certik because a few of their audited protocols ended up hacked?

Audit companies are building their reputation too. If the protocols they audit (and evaluated as safe) are exploited, then it shows lack of expertise. In fact, Certik has audited 3,422 projects, so no wonder some of them got hacked or had a bug.

Just having an audit doesn’t mean the protocol is safe. I’ve seen projects proudly announcing ‘Completed audit’, but when you read the audit the safety score is actually low.

The lesson is not to trust the announcements blindly, but verify the result by reading the actual audit.

What if you don’t read the audits?

The majority doesn’t read the audits anyway.

Knowing that Certik has a dashboard with all their audited projects. You can check the ‘Trust Score’ with higher number implying safety.

https://www.certik.com/

Other auditors like Hacken has a similar dashboard, or you could simply read the audit summary. Check the example, of Trader Joe’s audit done by Paladin.

You can see here that Trader Joe fixed high and medium severity issues, but not all low severity issues has been resolved.

https://paladinsec.co/projects/trader-joe-launchpeg/

Audit is just a start.

A lot more is needed to evaluate safety:

  • Adequate testing
  • Bounty campaigns
  • Documentation clarity
  • Admin controls
  • Oracle documentation

and much more… It’s a nightmare to verify it all yourself.

I really like what DefiSafety is doing. Its Process Quality Review verifies protocols and gives them a safety score.

https://www.defisafety.com/app?orderBy=finalScore

According to the PQR results, Liquity Protocol, Synthetix and Angle Protocol are the safest of all verified DeFi protocols.

On DefiSafety you can then check every element and see where the protocol scores the best/worst.

For example, Liquidy still needs Formal Verification.

Additionally, you can start by rating your portfolio safety on Exponential DeFi.

Its ‘Rate my wallet’ feature provides you with a custom risk analysis of your current investments. For example, $4.5M of Tetranode’s assets are deposited into riskier (C rank) protocols.

Elemental DeFi gives a score based on the project evaluation.Assessment takes into account asset risk, code quality and blockchain security to which the assets are deposited.

I like their easy to understand explanation of risks.

For example, take a look at Abracadabra’s MIM. It warns of SPELL being used as collateral which could result in bad debt.

If in doubt, ask!

Finally, I recommend joining the project community groups and ask:

Do they have an insurance fund?

Do they avoid questions?

What are they doing to increase security?

I asked Stargate team if they had an insurance fund in case they get hacked, but it sometimes more difficult to get an answer than I thought, which poses red flags.

But whatever happens, DeFi is still young, so better not to put all your assets into one protocol.

Do you have more useful tips how to evaluate projects and protect your assets?

Comments

All Comments

Recommended for you

  • Asian Equities Strong, CNH Falls Amid Tariff Threat and China Economic Work Conference Expectations

    Several Asian countries, including Indonesia, Japan, Pakistan, South Korea, Taiwan, and Thailand, experienced gains of over 1% in their equities. The offshore traded renminbi fell against the US dollar early in the trading day, which could be due to President Trump's recent tariff threat or the Euro's rough outing. The Hang Seng and Hang Seng Tech indexes rose in Hong Kong, with energy and financials leading the gains. The US government added more than 130 foreign companies to its "Entity List," which requires additional licensing, and 22 Chinese provinces have announced plans to refinance RMB 1.673tn of hidden debt. Copper and steel prices gained while treasury bond prices fell.

  • Bitcoin mining company Argo Blockchain raises £4.2 million via share subscription

    According to a report, Bitcoin mining company Argo Blockchain announced that it has raised £4.2 million through stock subscription. After this transaction, Argo's total issued shares have exceeded 717 million shares. It is reported that an unidentified institutional investor participated in this stock subscription. The new funds will help Argo relocate its Bitcoin mining facilities to Texas.

  • Public, an investment platform supporting crypto trading, completes $135 million in Series D-2 financing

    investment platform Public has raised $135 million in Series D financing through equity and debt financing, including $105 million in equity financing and $30 million in debt financing. Accel is the main investor. The platform has raised more than $300 million in total financing to date. Public announced the launch of cryptocurrency trading services in 2021, entering the digital currency battlefield and competing with Robinhood Markets and others. Previously, individual investors using the platform could only trade stocks listed in the United States and exchange-traded funds. Its target customers are young digital natives, and new funds will be used to improve its artificial intelligence capabilities.

  • Swish Ventures, owned by former NBA star Casspi, completes $60 million in funding

    former NBA star Omri Casspi has raised $60 million for his latest venture capital fund, Swish Ventures. Investors include Sequoia Capital, Ophir Ehrlich, founder of EON; Amiram Shachar, founder of Upwind; and Gal Ben-David and Alon Arvatz, co-founders of PointFive. The fund will reportedly invest in early-stage cybersecurity, cloud infrastructure, and artificial intelligence startups, including cybersecurity startups in the fintech and Web3 sectors, and plans to support 10 companies with each investment ranging from $5 million to $7 million.

  • Scam Sniffer releases November phishing report: $9,380,000 stolen, 9,208 victims

    Scam Sniffer released its November phishing report, which resulted in a total of $9,380,000 stolen and 9,208 victims, including:

  • Decentralized AI investment strategy analysis platform OpenPad AI completes $2 million financing, led by Basics Capital

    OpenPad AI, a data-driven investment strategy platform that utilizes decentralized AI analysis, has announced the completion of a $2 million financing round. Basics Capital led the investment, with participation from Protein Capital, Spicy Capital, Green Arrow Adventures, VivaTech Ventures, Brinc, Boba Network, Avalon Wealth Club, Coin Bold, and TechFarm. OpenPad AI combines blockchain technology with artificial intelligence, allowing users to access investment strategies, project ratings, and real-time market insights while maintaining control over their data.

  • Ethena Foundation awards multi-million dollar grant to Derive

    Derive (formerly known as Lyra), an options agreement protocol, announced a partnership with Ethena and officially joined the Ethena Network. As part of the partnership, the Ethena Foundation provided Derive with millions of dollars in grants, and sENA token holders will be eligible to receive 5% of the DRV token supply from Derive DAO.

  • Judge again rejects Musk's high compensation plan, Tesla to appeal

    a Delaware judge has once again rejected Musk's high salary plan at Tesla. Tesla's official social media responded to this by stating that the court's ruling was incorrect and that they will appeal. If this ruling is not overturned, it means that the judge and plaintiff's lawyers are managing Delaware companies rather than their legitimate owners - shareholders.

  • Norway’s Wealth Fund Watchdog to Review Cryptocurrencies by 2025

    According to market news reported by , the supervisory authority of Norway's wealth fund will conduct reviews on shoe manufacturers, cryptocurrency, and gambling companies in 2025, which may lead to divestment.

  • DeFi TVL exceeds $95 billion again

    According to defillama data, as of May 18, 2024, the total value locked (TVL) in DeFi has once again surpassed $95 billion. It is currently reported at $95.069 billion, an increase of nearly $12 billion from the low point of $83.04 billion 35 days ago. Among the top five protocols in terms of TVL, Eigenlayer has the highest 30-day increase, with TVL rising by 19.67% to a total of $15.455 billion.